4 ms·
The problem with this approach is that you get exposed when a website stores their passwords as plaintext. Someone who was smart enough to notice the pattern i
by duncanj 15y ago
The problem with this approach is that you get exposed when a website stores their passwords as plaintext. Someone who was smart enough to notice the pattern in your formula could then use that info to get at your other accounts.
- dave1010uk 15y agoVery true, though the ease of breaking this would vary widely based on the formula and the master password. If you knew my Facebook password was "CheeseFace" then you'd guess that my Twitter one was "CheeseTwit" but if you knew my Facebook password was "rsuifhskjcv" then you have no idea that my Twitter one was "rsuifhsksuw".
- bigiain 15y agoDid you notice one of the passwords mentioned as being found in readily available rainbow tables was 1qazZAQ! - the leftmost column of keysn a keyboard down then up-with-shift-held-down. That's an indication that the password cracking community is perfectly aware of "keyboard pattern" passwords.
- dave1010uk 15y agoIt makes sense that attackers are likely to know the steps we take to make secure passwords but a password that's been "keyboard shifted" would be slightly more secure as it is an extra variation for a dictionary to include.